{AC2DC2EF-5165-40A3-8CDF-41DCA1B0901A}
[AM] 35. c:\windows\system32\shlhook.dll
Beijing Rising Technology Co., Ltd.
shlhook Module
.text,.rdata,.data,.rsrc,.reloc,
+ 用户登陆自运行项目
+ HKLM\Software\Microsoft\Windows\CurrentVersion\Run
nwiz
[A ] 36. c:\windows\system32\nwiz.exe
.text,.rdata,.data,.rsrc,
RTHDCPL
[AM] 37. c:\windows\rthdcpl.exe
Realtek Semiconductor Corp.
Realtek HD Audio Control Panel
.text,.data,.tls,.rdata,.idata,.edata,.rsrc,.reloc,
Alcmtr
[A ] 38. c:\windows\alcmtr.exe
Realtek Semiconductor Corp.
Realtek Azalia Audio - Event Monitor
.text,.rdata,.data,.rsrc,
HP Software Update
[AM] 39. c:\program files\hp\hp software update\hpwuschd2.exe
Hewlett-Packard Co.
Hewlett-Packard Product Assistant
.text,.rdata,.data,.rsrc,
RavTask
[AM] 40. d:\program. files\rising\rav\ravtask.exe
Beijing Rising Technology Co., Ltd.
RavTimer
.text,.rdata,.data,.rsrc,
RfwMain
[AM] 41. d:\program. files\rising\rfw\rfwmain.exe
Beijing Rising Technology Co., Ltd.
Rising Personal FireWall Main Program
.text,.rdata,.data,.rsrc,
runeip
[AM] 42. c:\program files\rising\antispyware\runiep.exe
Beijing Rising Technology Co., Ltd.
Rising AntiSpyware Monitor
.text,.rdata,.data,.rsrc,
+ 开机执行
+ HKLM\SYSTEM\CurrentControlSet\Control\NetworkProvider\Order
BootExecute
[A ] 43. c:\windows\system32\bsmain.exe
Beijing Rising Technology Co., Ltd.
Rising Antivirus 2008
.text,.rdata,.data,.rsrc,.reloc,
[A ] 44. c:\windows\system32\kknative.exe
Beijing Rising Technology Co., Ltd.
NativeAp
.text,.data,.rsrc,.reloc,
+ 映像劫持
+ HKCR\.html
htmlfile\open\Command
[AM] 45. d:\program. files\tencent\tt\bin\ttraveler.exe
Tencent
.text,.rdata,.data,TT_Share,.rsrc,
htmlfile\TencentTraveler\Command
[AM] 45. d:\program. files\tencent\tt\bin\ttraveler.exe
Tencent
.text,.rdata,.data,TT_Share,.rsrc,
+ HKCR\.htm
htmlfile\open\Command
[AM] 45. d:\program. files\tencent\tt\bin\ttraveler.exe
Tencent
.text,.rdata,.data,TT_Share,.rsrc,
htmlfile\TencentTraveler\Command
[AM] 45. d:\program. files\tencent\tt\bin\ttraveler.exe
Tencent
.text,.rdata,.data,TT_Share,.rsrc,
+ 程序初始化和已知动态连接库
+ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
[AM] 46. c:\windows\system32\ieprot.dll
Beijing Rising Technology Co., Ltd.
IE Protector
.text,.rdata,.data,.rsrc,.reloc,
+ 正在运行的进程
+ 000000d0(208) RavStub.exe
00400000[00021000]
[ M] 47. d:\program. files\rising\rav\ravstub.exe
Beijing Rising Technology Co., Ltd.
Rising RavStub
.text,.rdata,.data,.rsrc,
10000000[0001F000]
[ M] 48. d:\program. files\rising\rav\proccom.dll
Beijing Rising Technology Co., Ltd.
ProcessC Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00620000[00024000]
[ M] 49. d:\program. files\rising\rav\rscommx2.dll
Beijing Rising Technology Co., Ltd.
RsCommX2
.text,.rdata,.data,.rsrc,.reloc,
23700000[00028000]
[ M] 50. d:\program. files\rising\rav\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 000000fc(252) flashget.exe
00400000[001F2000]
[AM] 28. d:\program. files\flashget\flashget.exe
FlashGet.com
FlashGet
.text,.rdata,.data,.rsrc,
10000000[0009D000]
[ M] 53. d:\program. files\flashget\fgbtcore.dll
BT动态链接库
.text,.rdata,.data,.rsrc,.reloc,
00390000[00009000]
[ M] 54. c:\windows\system32\normaliz.dll
Microsoft Corporation
Unicode Normalization DLL
.text,.data,.rsrc,.reloc,
42990000[00045000]
[ M] 55. c:\windows\system32\iertutil.dll
Microsoft Corporation
Run time utility for Internet Explorer
.text,.data,.rsrc,.reloc,
00600000[0014C000]
[ M] 56. d:\program. files\flashget\fgemcore.dll
EM动态链接库
.text,.rdata,.data,.rsrc,.reloc,
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
010A0000[0000C000]
[ M] 57. d:\program. files\flashget\debugrpt.dll
flashget
debugrpt
.text,.rdata,.data,.rsrc,.reloc,
011B0000[0016F000]
[ M] 58. c:\windows\system32\nview.dll
.text,.rdata,.data,.idata,.rsrc,.reloc,
013E0000[00028000]
[ M] 59. c:\windows\system32\nvwrszhc.dll
NVIDIA Corporation
NVIDIA nView Desktop and Window Manager
.rsrc,.reloc,
01410000[0002D000]
[ M] 60. c:\program files\tencent\ssplus\splus1.dll
TENCENT
.text,.rdata,.data,Shared_T,Shared_H,.rsrc,.reloc,
42EF0000[005CD000]
[AM] 24. c:\windows\system32\ieframe.dll
Microsoft Corporation
Internet Explorer
.text,.data,.rsrc,.reloc,
02440000[00015000]
[ M] 61. c:\windows\system32\nvwddi.dll
NVIDIA Corporation
NVIDIA nView Display Driver Interface Lib, Version 83.91
.text,.rdata,.data,.shared,.rsrc,.reloc,
02470000[0000D000]
[ M] 62. d:\program. files\flashget\fgmgr.dll
www.flashget.com Flashget BHO Manager
.text,.rdata,.data,.rsrc,.reloc,
02580000[0002D000]
[ M] 63. d:\program. files\flashget\fgupdate.dll
www.flashget.com fgupdate.dll
.text,.rdata,.data,.idata,.IShareX,.rsrc,.reloc,
02C90000[00028000]
[ M] 64. d:\program. files\rising\rav\ravscrch.dll
Beijing Rising Technology Co., Ltd.
RavScrCh Module
.text,.rdata,.data,.rsrc,.reloc,
72C80000[00008000]
[ M] 65. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
+ 00000138(312) RfwMain.exe
00400000[00092000]
[AM] 41. d:\program. files\rising\rfw\rfwmain.exe
Beijing Rising Technology Co., Ltd.
Rising Personal FireWall Main Program
.text,.rdata,.data,.rsrc,
7C140000[00103000]
[ M] 66. c:\windows\system32\mfc71.dll
Microsoft Corporation
MFCDLL Shared Library - Retail Version
.text,.data,.rsrc,.reloc,
7C340000[00056000]
[ M] 67. c:\windows\system32\msvcr71.dll
Microsoft Corporation
Microsoft? C Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
7C3A0000[0007B000]
[ M] 68. c:\windows\system32\msvcp71.dll
Microsoft Corporation
Microsoft? C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
26600000[000B8000]
[ M] 69. d:\program. files\rising\rfw\rsguilib.dll
Beijing Rising Technology Co., Ltd.
Rising GUI Library Loader
.text,.rdata,.data,.rsrc,.reloc,
10000000[0001F000]
[ M] 70. d:\program. files\rising\rfw\proccom.dll
Beijing Rising Technology Co., Ltd.
ProcessC Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00B50000[00024000]
[ M] 71. d:\program. files\rising\rfw\rscommx2.dll
Beijing Rising Technology Co., Ltd.
RsCommX2
.text,.rdata,.data,.rsrc,.reloc,
00C90000[0000E000]
[ M] 72. d:\program. files\rising\rfw\rsappmgr.dll
Beijing Rising Technology Co., Ltd.
Rising Application Manager
.text,.rdata,.data,.rsrc,.reloc,
00CB0000[00030000]
[ M] 73. d:\program. files\rising\rfw\cfgdll.dll
Beijing Rising Technology Co., Ltd.
CfgDll
.text,.rdata,.data,.rsrc,.reloc,
23700000[00028000]
[ M] 74. d:\program. files\rising\rfw\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00EF0000[00014000]
[ M] 75. d:\program. files\rising\rfw\rfwctrl.dll
Beijing Rising Technology Co., Ltd.
RfwCtrl DLL
.text,.rdata,.data,.rsrc,.reloc,
23800000[00018000]
[ M] 76. d:\program. files\rising\rfw\rsxml.dll
Beijing Rising Technology Co., Ltd.
RsXML
.text,.rdata,.data,.rsrc,.reloc,
23900000[00040000]
[ M] 77. d:\program. files\rising\rfw\pngdll.dll
Beijing Rising Technology Co., Ltd.
Rising .Png File Loader Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
014B0000[0000F000]
[ M] 78. d:\program. files\rising\rfw\rfwrule.dll
Beijing Rising Technology Co., Ltd.
rule DLL
.text,.rdata,.data,.rsrc,.reloc,
+ 000001a8(424) spoolsv.exe
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 00000284(644) smss.exe
+ 000002d0(720) csrss.exe
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 000002ec(748) winlogon.exe
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
72C80000[00008000]
[ M] 65. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
+ 00000318(792) services.exe
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 00000324(804) lsass.exe
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 000003c4(964) svchost.exe
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 00000400(1024) svchost.exe
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 00000460(1120) CCenter.exe
00400000[00029000]
[AM] 4. d:\program. files\rising\rav\ccenter.exe
Beijing Rising Technology Co., Ltd.
CCenter
.text,.rdata,.data,.rsrc,
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 00000480(1152) svchost.exe
00FF0000[00009000]
[ M] 54. c:\windows\system32\normaliz.dll
Microsoft Corporation
Unicode Normalization DLL
.text,.data,.rsrc,.reloc,
42990000[00045000]
[ M] 55. c:\windows\system32\iertutil.dll
Microsoft Corporation
Run time utility for Internet Explorer
.text,.data,.rsrc,.reloc,
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 000004bc(1212) stormliv.exe
00400000[00077000]
[ M] 79. d:\program. files\stormii\stormliv.exe
北京暴风网际科技有限公司
暴风影音媒体控制中心
.text,.rdata,.data,.rsrc,
75FF0000[00065000]
[ M] 80. d:\program. files\stormii\msvcp60.dll
Microsoft Corporation
Microsoft (R) C++ Runtime Library
.text,.rdata,.data,.rsrc,.reloc,
00380000[00009000]
[ M] 54. c:\windows\system32\normaliz.dll
Microsoft Corporation
Unicode Normalization DLL
.text,.data,.rsrc,.reloc,
42990000[00045000]
[ M] 55. c:\windows\system32\iertutil.dll
Microsoft Corporation
Run time utility for Internet Explorer
.text,.data,.rsrc,.reloc,
+ 000004c4(1220) RTHDCPL.EXE
00400000[01027000]
[AM] 37. c:\windows\rthdcpl.exe
Realtek Semiconductor Corp.
Realtek HD Audio Control Panel
.text,.data,.tls,.rdata,.idata,.edata,.rsrc,.reloc,
72C80000[00008000]
[ M] 65. c:\windows\system32\msacm32.drv
Microsoft Corporation
Microsoft Sound Mapper
.text,.data,.rsrc,.reloc,
10000000[0016F000]
[ M] 58. c:\windows\system32\nview.dll
.text,.rdata,.data,.idata,.rsrc,.reloc,
02550000[00028000]
[ M] 59. c:\windows\system32\nvwrszhc.dll
NVIDIA Corporation
NVIDIA nView Desktop and Window Manager
.rsrc,.reloc,
02580000[0002D000]
[ M] 60. c:\program files\tencent\ssplus\splus1.dll
TENCENT
.text,.rdata,.data,Shared_T,Shared_H,.rsrc,.reloc,
+ 000004dc(1244) svchost.exe
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
+ 00000508(1288) HPWuSchd2.exe
00400000[0000C000]
[AM] 39. c:\program files\hp\hp software update\hpwuschd2.exe
Hewlett-Packard Co.
Hewlett-Packard Product Assistant
.text,.rdata,.data,.rsrc,
70000000[00019000]
[ M] 51. d:\program. files\rising\rfw\ijt_base.dll
Beijing Rising Technology Co., Ltd.
Inject Base
.text,.rdata,.data,.rsrc,.reloc,
60000000[0000F000]
[ M] 52. d:\program. files\rising\rfw\olemon.dll
Beijing Rising Technology Co., Ltd.
Ole Mon Dll
.text,.rdata,.data,.rsrc,.reloc,
10000000[0002D000]
[ M] 60. c:\program files\tencent\ssplus\splus1.dll
TENCENT
.text,.rdata,.data,Shared_T,Shared_H,.rsrc,.reloc,
00AA0000[0016F000]
[ M] 58. c:\windows\system32\nview.dll
.text,.rdata,.data,.idata,.rsrc,.reloc,
00D40000[00028000]
[ M] 59. c:\windows\system32\nvwrszhc.dll
NVIDIA Corporation
NVIDIA nView Desktop and Window Manager
.rsrc,.reloc,
+ 00000538(1336) RavTask.exe
00400000[00034000]
[AM] 40. d:\program. files\rising\rav\ravtask.exe
Beijing Rising Technology Co., Ltd.
RavTimer
.text,.rdata,.data,.rsrc,
10000000[0001F000]
[ M] 48. d:\program. files\rising\rav\proccom.dll
Beijing Rising Technology Co., Ltd.
ProcessC Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00A30000[00024000]
[ M] 49. d:\program. files\rising\rav\rscommx2.dll
Beijing Rising Technology Co., Ltd.
RsCommX2
.text,.rdata,.data,.rsrc,.reloc,
23700000[00028000]
[ M] 50. d:\program. files\rising\rav\rscommon.dll
Beijing Rising Technology Co., Ltd.
Rising Common Function Dynamic Link Library
.text,.rdata,.data,.rsrc,.reloc,
00C90000[0000E000]
[ M] 81. d:\program. files\rising\rav\rsappmgr.dll
Beijing Rising Technology Co., Ltd.
Rising Application Manager
.text,.rdata,.data,.rsrc,.reloc,